Skip to main content

SigmaShake Guardrails for Grok Bot

SigmaShake Guardrails evaluates AI tool calls against SSG rules (ALLOW/DENY/ASK/FORCE/LOG/SHADOW) and provides honest-agent safeguards — integration-dependent guardrails, not a sandbox.

Transport selection (local vs hosted)​

Use one or both. Prefer local when a reachable machine has ssg installed; keep hosted as the remote fallback (additive — do not remove hosted when enabling local).

PreferenceWhenHow
Local stdio (preferred when available)Grok Bot / Cursor can spawn on a machine with ssg (your Mac, machine-targeted tools, ssg init --client=grok-bot)ssg mcp-server --client=grok-bot via ~/.cursor/mcp.json server ssg-governance-grok-bot, or plugin pack mcp.local.json → sigmashake-guardrails-local
Hosted Streamable HTTP (default marketplace)No local ssg, or remote-only connector on the bot computerPlugin mcp.json → POST https://mcp.sigmashake.com/mcp with Authorization: Bearer <license-key>

Client name: always --client=grok-bot (adapter id). Do not use --client=grok here — that is the separate Grok CLI adapter.

If both servers are registered, call eval tools on the local server first (ssg-governance-grok-bot / sigmashake-guardrails-local); fall back to hosted sigmashake-guardrails when local tools are missing or unreachable.

Install (hosted — marketplace default)​

Landing page: grok.sigmashake.com

  1. Subscribe at sigmashake.com/pricing and copy your license key.
  2. Install the SigmaShake Guardrails plugin from the Cursor Marketplace (submit path: cursor.com/marketplace/publish) or from the public pack github.com/sigmashakeinc/sigmashake-guardrails.
  3. Set SSG_LICENSE_KEY under Plugins → Configure.
  4. Confirm health: GET https://mcp.sigmashake.com/health.

Install (local stdio — additive)​

When ssg is on the machine Grok Bot can reach:

ssg init --client=grok-bot

That writes/merges ~/.cursor/mcp.json (and project .cursor/mcp.json) with:

{
"mcpServers": {
"ssg-governance-grok-bot": {
"command": "ssg",
"args": ["mcp-server", "--client=grok-bot"],
"env": { "SSG_CLIENT": "grok-bot" }
}
}
}

Or copy the plugin pack's mcp.local.json entry (sigmashake-guardrails-local) into Cursor MCP settings / Grok Bot Add MCP server (stdio):

  • command: ssg (or absolute path, e.g. /opt/homebrew/bin/ssg / ~/.local/bin/ssg)
  • args: mcp-server, --client=grok-bot
  • env: SSG_CLIENT=grok-bot

Leave the hosted plugin entry in place for fallback.

MCP endpoints​

TransportURL / command
Local stdio (when ssg reachable)ssg mcp-server --client=grok-bot
Streamable HTTP (hosted)POST https://mcp.sigmashake.com/mcp
Legacy SSEGET https://mcp.sigmashake.com/sse then POST /message
Health (hosted)GET https://mcp.sigmashake.com/health

Hosted auth: Authorization: Bearer <license-key>.

Decisions​

ALLOW, DENY, ASK, FORCE, LOG, SHADOW. If eval is unavailable, fail closed on destructive, secret, irreversible, or rule-mutation actions.

Never create, edit, delete, or sync live SSG rules (*.rules, .sigmashake/rules/, ssg_write_rule, ssg rule sync, ssg hub pull into a live rules dir). Draft rule text in chat only.

These are honest-agent safeguards, not a kernel sandbox. Do not invent SHAKEDOWN numbers.

See also: MCP Server, Client Adapters, Agent Install Guide.